DE version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⥠Community Insights
Discussion Sentiment
71% Positive
Analyzed from 1849 words in the discussion.
Trending Topics
#french#data#tax#trust#found#since#france#nice#lost#hacked

Discussion (51 Comments)Read Original on HackerNews
- The last two sections (â20% of the article, 5.Cloud and 6.IA) are barely relevant.
- Some comparisons are questionable. It claims that, since some taxes data was compromised, the trust in the national Federated Identity is eroded "as if Facebook Connect was hacked". That's strange, I think it should be "as the trust in Facebook Connect would be eroded when Facebook is hacked". Anyway, I think most people won't care.
- Some sentences make no sense: "Le piratage de Ficoba semble en ĂŞtre l'exemple type"... But "Ficoba" is not mentioned anywhere, and, though I know what the word means, I can't guess what the sentence points to.
The OP should have mentioned another important hack of French national structures that happened in december 2025 and which is well documented. IIRC, through phishing, a keylogger was installed on a teacher's computer. Then the hackers got credentials to an internal training platform for teachers. Then they exploited multiple security breaches and connections between Ministries to get access to the national police files.
The taxes services is one of the oldest online government service in France that has existed, with a very wide usage.
As people had already that authentication as an identity provider, it was natural to reuse that authentication (not the password, but 3rd party auth Ă la OAuth, but a french government standard) to authenticate to government services that went online later.
So if the taxes auth is compromised (so far I haven't seen enough details about the coverage of the leak), that's a real concern.
Got hacqued.
Most media outlets will use "pirate informatique" (or just "pirate") when talking about hackers, and "piratage" for hacking. Example: [2]
[0] https://en.wikipedia.org/wiki/Office_qu%C3%A9b%C3%A9cois_de_...
[1] https://vitrinelinguistique.oqlf.gouv.qc.ca/resultats-de-rec...
[2] https://www.lapresse.ca/actualites/justice-et-faits-divers/2...
While in Singapore I was able to get ahold of some policeman who made some calls and was told it was waiting for me at the Lost and Found inside the Nice airport gift shop. I thanked him and made 24 hour layover in Nice.
Well, getting to the airport, I came tk this shop. I asked about the âsac a dos grisâ in the other room. They checked their ordinateur: âNO, je suis desoleeâ. Sorry sir! I said you definitely have it, can you please go to that other room and check? âNo sorry we cannot. It is not here. After a week we give things to the municipal lost and found. At the polics station. Go there.â
The day was ending (French govt services work til 4pm) so I raced to the municipal police station in Nice. I arrive and they have a bunch of keys and other things people lost around the city. I barely speak French but luckily a middle-aged lady was there who spoke good English. She helped me ask them. âNo. Sorry. It is not here.â Are they sure? âYes, we checked. Not here.â
She gave me a ride on her vespa (she had a motorcycle) and I treated her to dinner while we discussed the situation. We agreed I should go to the central police station after that and file a missing item report. Which I did (spoiler alert: doesnât do anything, but standing in line is less than in US cities).
That night I chose to stay at some rinkydink place in Nice, because why not (I was by myself) and got up around 4am to take the bus to the tram networkâs lost and found â the last place it could be. I would have aittle time before my flight.
In the morning I got up early and got to that Lost and Found, before my flight. I had one hour. It was located near a university, and after wandering around I had found the little enclave. The staff there were very nice â but they didnât have it either!
I flew home, dejected. My backups hadnât been perfect; I had a lot of stuff on that computer, including an iOS App on XCode that I had to release to a lot of people! (And a couple Metamask wallets.)
Anyway I kept in touch with the nice policeman throughout. He went to the airport lost and found - the same one which refused to check the other room because their computer said it wasnât there â and CONFIRMED that my bag was there. They had let him check the back room, you see!
But I wasnât in Nice anymore. I filled out a âtroov.comâ report and explained where it was. They had found it! Paid for FedEx. Over the next few days thanks to the Tracking I saw it go to the central station in France and then sent back. Because it was missing a customs form for USA. I had filled out that form, but something had been wrong. I had spoken to the main FedEx customs-facing team in Memphis for a few days, and they thought it was in USA already. They were wrong. Their system was also blind to this. Anyway, I saw it go back to that airport lost and found, a week later. Lost about $100âŚ
Then, the lady offered to come pick it up for me. She came, and was thankfully given this bag. She mailed it with DHL, and I received it. It was really overjoyed when it finally arrived, a month and a half after I had lost it! I of course sent the lady a payment to cover the cost. She did not want any other compensation. We are still friends to this day, and when my dad goes to France, I am putting them in touch.
One moral from this story is: French employees love to say âNoâ to anything and everything. If their computer says the thing isnât there, they wonât budge even when itâs the easiest thing to just check the other room manually. Unless you are a local policeman!
The other moral - back up your stuff! Have SyncThing or your own machine in the cloud. Especially if you travel to conferences, like me.
Les mois suivants, des individus se prĂŠsentent au domicile de licenciĂŠs en se faisant passer pour des policiers ou des gendarmes, parfois en tenue, pour se faire remettre des armes. Des vols sont constatĂŠs Ă Nice, Ă Paris, Ă Limoges, Ă DĂŠcines."
Sounds like a far fetched movie!
For government services, they are getting more and more common, it's scary.
Anyway, the main problem is that the breaches into the many French national data stores seem increasingly frequent.
Those same countries that treat financial privacy as axiomatic are trying their best to undermine chat encryption and would throw ed Snowden in prison given half a chance.
It's probably the quickest way to punish those people, just regular data leaks from the tax bureau.
I'm probably too optimistic, since this data is probably not admissible in court.
My guess is since a global conflict is ramping up this is only the beginning and we are about to see some real damage.
It is fairly easy to create chaos in a country for a few weeks if you start disrupting the grid, payments or internet access.
Weak.
* French tax authority (DGFiP) breach âş ~678,000 records leaked, names, tax bracket, reference income, withholding rate
* Detection gap âş intrusion spotted and cut off in late June, but the actual data theft wasn't discovered until the stolen data went up for sale on Aug 12, over a month later
* Second breach, same attacker âş land registry (cadastre) systems, late July, claimed 2M+ people affected, alleged MFA bypass
* Third incident âş French Ministry of Education systems also compromised in late July (staff data since 2001), disclosed quietly with little press coverage
* Legal precedent cited âş a 2023 EU Court of Justice ruling (stemming from Bulgaria's 2019 tax agency breach) established that fear of misuse alone counts as damage, and shifts the burden of proof onto the agency to show its security was adequate
* Root cause argument âş legacy "trust everything once you're inside" architecture, opposite of zero-trust, extended via remote/VPN access since COVID without redesigning the underlying trust model
* Systemic issue âş France's NIS2 transposition law has been stalled in parliament since 2024, partly over a dispute involving encryption backdoor provisions
* Broader angle âş piece also covers AI's growing role on the offensive side of cybersecurity, and the US scaling back international cyber-cooperation efforts through 2025â2026
How many workplaces have I seen like this? A tale as old as IT.
I was wondering how they would find a way to blame the United States.
And kids are back to school in one week.